We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-12539

Elasticsearch Incorrect Authorization



Description

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Reserved 2024-12-11 | Published 2024-12-17 | Updated 2024-12-17 | Assigner elastic


MEDIUM: 6.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

8.16.0
affected

References

discuss.elastic.co/...h-8-16-2-8-17-0-security-update/372091

cve.org (CVE-2024-12539)

nvd.nist.gov (CVE-2024-12539)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-12539

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.